<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Gamification as a Tool for Elevating Password Strength Awareness</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Miloš Kostić</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Igor Saveljić</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Faculty of Information Technology, Belgrade Metropolitan University</institution>
          ,
          <addr-line>Tadeuša Košćuška 63, 11000 Belgrade</addr-line>
          ,
          <country country="RS">Serbia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In modern society, where users are confronted with the necessity of managing an ever-growing number of personal profiles and accounts, low password security awareness remains a significant vulnerability in cybersecurity. Despite the existence of numerous tools designed for password safekeeping, educating users and broadening their knowledge of password strength and related cybersecurity risks cannot be understated. The popularity of gamification as an educational technique for overcoming challenges in diferent domains, mostly related to the lack of motivation and attention, has grown in recent years. This paper explores the concept of a two-dimensional game in which players face specific challenges aimed at replacing existing weak passwords with new, stronger ones, while avoiding the loss of access to various platforms. Time constraints and simulated cyber-attacks enhance the learning process and underscore the importance of the analyzed topic.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Gamification</kwd>
        <kwd>Security awareness</kwd>
        <kwd>Games-based learning</kwd>
        <kwd>Human-centered cybersecurity</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <sec id="sec-1-1">
        <title>In the digital age, our society increasingly relies on the</title>
        <p>Internet for various aspects of our lives, from banking The Internet presents numerous potential risks when
to e-commerce. Transactions conducted online often browsing the web, such as interacting with malicious
require the exchange of personal information, such as websites and domains, using inadequately constructed
home addresses and credit card details. Within this digital and weak passwords, responding to phishing emails and
landscape, passwords continue to serve as the primary messages etc. These risks can place users in dangerous
authentication mechanism for accessing online services. situations [1]. Various methods have been employed to
Ensuring users remain secure while using passwords is of raise user security awareness during online transactions.
paramount importance. This paper seeks to address the With the prevalence of password-related vulnerabilities,
critical need to enhance security awareness and promote research eforts have predominantly concentrated on the
better password practices through the implementation creation and enhancement of security awareness tools
of gamification techniques. aimed at fortifying password security.</p>
        <p>Importance of raising password strength awareness Users often grapple with the creation and retention
and concept of gamification and its application within of strong, secure passwords, leading to various studies
the context of the learning environment will be explored aimed at addressing this issue [2, 3, 4]. Experience has
within this paper. Additionally, an concept overview of a revealed that the prevalent method of incorporating
passtwo-dimensional game (“Lockedout”) in which players word meters into password creation forms can frequently
face specific challenges aimed at replacing existing weak create a false sense of security. This is often attributed
passwords with new, stronger ones, while avoiding the to the shortcomings in many of the available password
loss of access to various platforms will be presented. meter algorithms, which may incorrectly label weak or
poorly defined passwords as strong [ 5, 6]. Research
suggests that additional factors should be considered when
using password meters, such as user perceptions of
account importance, as opposed to solely relying on the
feedback provided by the meter. It becomes evident that
BISEC’23: 14th International Conference on Business Information password meters alone may not be suficient in raising
Security, November 24, 2023, Niš, Serbia awareness and encouraging the creation of secure
pass* Corresponding author. words.
$ milos.kostic@metropolitan.ac.rs (M. Kostić); Persuasive messages intended to instill fear by
outlinigo0r.0s0a9v-e0lj0i0c@5-0m9e1t2r-o9p5o1l8it(aMn..aKc.orsst(iIć.);S0a0v0e0lj-i0ć0)02-0707-5174 ing the possible consequences of non-compliance have
(I. Saveljić) also been investigated as a means to boost security
aware© 2024 Copyright for this paper by its authors. Use permitted under Creative Commons License ness. By educating end-users on the importance of
passCPWrEooUrckReshdoinpgs IhStpN:/c1e6u1r3-w-0s.o7r3g ACttEribUutRion W4.0oInrtekrnsahtioonpal (PCCroBYce4.0e).dings (CEUR-WS.org)
word strength and heightening their awareness of
associated risks, this approach has proven efective in
motivating users to craft more robust passwords.</p>
        <p>Despite ongoing eforts, issues with password hygiene
persist, highlighting the necessity for more efective ways
to convey password security information to users.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>3. Gaminfication</title>
      <p>Gamification is often described as the application of game
design principles in non-gaming contexts [6, 7]. However,
it encompasses more than just incorporating elements
from games. It encompasses the infusion of game
thinking into non-game scenarios, involving elements such as:
player control, rewards, progress mechanics,
collaborative problem-solving, storytelling, and even competition.</p>
      <p>At its core, gamification seeks to motivate individuals
to change their behavior, primarily through enhanced
engagement and motivation.</p>
      <p>Research and recent studies have unveiled numerous
instances where competitive elements successfully
encouraged participants to change their behavior [6, 8]. The
inclusion of competitive and cooperative elements in non- Figure 2: Password change UI.
game contexts exemplifies the integration of gamification.</p>
      <p>Such gamified contexts provide a safe environment for
participants to practice and hone their skills under pres- 4.1. Game Structure
sure, fostering an environment of controlled learning
and adaptation. Despite the growing popularity of digital In terms of UI/UX elements, "Lockedout" will revolve
or online gamified environments, gamification can also around the visible borders of a computer monitor,
featurbe seamlessly incorporated into tabletop contexts, using ing a fictional operating system (OS) hosting five
simuelements from card games or board games. lated computer applications. Additionally, an OS Guard,</p>
      <p>Studies consistently indicate a preference for gami- akin to antivirus software, will facilitate player
interacifed environments over their non-gamified counterparts tions within the game and provide essential narrative
among participants. The advantages of increased engage- elements and guidance (Figure 2.). Each of the computer
ment, motivation, and skill development make gamifica- applications will possess its own interface, complete with
tion an attractive proposition for cybersecurity educa- predefined content, and will serve as representations of
tion and awareness. Nevertheless, a detailed investiga- significant daily activities necessitating robust password
tion into the precise application of gamification within protection:
existing cybersecurity awareness contexts remains an
underexplored area.
4. “Lockedout” – Game concept
"Lockedout" is a 2D pixel art time challenge game
designed to educate players about prevalent cybersecurity
risks and underscore the critical importance of password
strength. It embraces a pixelated aesthetic reminiscent
of video games from the 1980s and 1990s, deliberately
chosen to infuse a sense of charm and playfulness into
the overall gaming experience.</p>
      <p>The game’s title (Figure 1.), "Lockedout," is a wordplay
carefully selected to convey the concept of being virtually
locked out due to password-related issues.
• Email communication
• Socializing with friends
• Online shopping
• Engaging with social media
• Managing bank account and transactions</p>
      <sec id="sec-2-1">
        <title>A fully operational password checker, featuring a pass</title>
        <p>word strength indicator and corrective notifications, will
serve as a key gameplay mechanic. The flow of gameplay
will be regulated by a predefined scenario and relevant
timers.</p>
        <p>An imaginary hacker or hacker group will also be
featured in the narrative; however, they will not be directly
portrayed within the game.
4.2. Gameplay scenario
their city. As the player begins to respond to the message
(or when a short timer elapses due to player inactivity),
they are abruptly logged out of the chat application.</p>
        <p>An OS Guard notification then appears, warning the
player of an ongoing cyberattack (Figure 6) and
prompting them to change their password to protect their
account. Subsequent pop-ups follow, indicating attacks on
other applications, heightening tension.</p>
        <p>Each app screen displays a red timer, reflecting the time
remaining for the player to enter their old password and
generate a new, robust one. Timer durations are based on
the application’s importance, with the bank application’s
timer set to the shortest duration, emphasizing its critical
nature. The chat and social media apps enjoy slightly</p>
      </sec>
      <sec id="sec-2-2">
        <title>Upon a short interval, a visual and audio notification</title>
        <p>triggers within the “Chat” app (Figure 5), revealing a
message from a friend inquiring about recent data breaches in
diferent dificulty levels will be implemented to cater to
beginners and more advanced users.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>5. Conclusion and future work</title>
      <p>The game’s narrative seamlessly integrates educational
content into the player’s journey, resulting in an
engaging and immersive learning experience. It ensures that Acknowledgment
players develop a nuanced understanding of the risks
associated with weak passwords, highlighting poor prac- This paper was supported by the Blockchain
Technoltices such as storing login data in easily accessible loca- ogy Laboratory at Belgrade Metropolitan University,
Beltions like sticky notes or files on the computer desktop. grade, Serbia.</p>
      <p>"Lockedout" ofers in-game tutorials and pop-up tips
to educate players on password strength, complexity, and References
the significance of unique passwords. Real-time feedback
on password strength, accompanied by explanations of [1] L. A. Shepherd, J. Archibald, R. I. Ferguson,
Percepthe criteria for robust passwords, enhances the learning tion of risky security behaviour by users: Survey of
process. current approaches, in: Human Aspects of
Informa</p>
      <p>After each playthrough, an informative summary re- tion Security, Privacy, and Trust: First International
inforces the importance of sound password practices, Conference, HAS 2013, Held as Part of HCI
Interproviding practical guidance. Furthermore, a dedicated national 2013, Las Vegas, NV, USA, July 21-26, 2013.
section invites players to delve deeper into the subject, Proceedings 1, Springer, 2013, pp. 176–185.
ofering supplementary resources to expand their knowl- [2] S. L. Pfleeger, D. D. Caputo, Leveraging behavioral
edge. science to mitigate cyber security risk, Computers</p>
      <p>To ensure that game is accessible to players with vari- &amp; security 31 (2012) 597–611.
ous levels of gaming and technical experience, potentially
[3] S. Cohen, W. Nutt, Y. Sagiv, Deciding equivalences
among conjunctive aggregate queries, Journal of the</p>
      <p>ACM (JACM) 54 (2007) 5–es.
[4] J. M. Stanton, K. R. Stam, P. Mastrangelo, J. Jolton,</p>
      <p>Analysis of end user security behaviors, Computers
&amp; security 24 (2005) 124–133.
[5] X. D. C. D. Carnavalet, M. Mannan, A large-scale
evaluation of high-impact password strength
meters, ACM Transactions on Information and System</p>
      <p>Security (TISSEC) 18 (2015) 1–32.
[6] S. Scholefield, L. A. Shepherd, Gamification
techniques for raising cyber security awareness, in: HCI
for Cybersecurity, Privacy and Trust: First
International Conference, HCI-CPT 2019, Held as Part of
the 21st HCI International Conference, HCII 2019,
Orlando, FL, USA, July 26–31, 2019, Proceedings 21,</p>
      <p>Springer, 2019, pp. 191–203.
[7] G. Fink, D. Best, D. Manz, V. Popovsky, B.
Endicott</p>
      <p>Popovsky, Gamification for measuring cyber
security situational awareness, in: Foundations of
Augmented Cognition: 7th International Conference,
AC 2013, Held as Part of HCI International 2013,
Las Vegas, NV, USA, July 21-26, 2013. Proceedings 7,</p>
      <p>Springer, 2013, pp. 656–665.
[8] I. Rief, Systematically applying gamification to
cyber security awareness trainings, 2018.</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>